KOP Integrations - Ping One - Rafay Product Documentation

Integration with SAML

Follow the steps documented below to integrate your Org and PingOne Tenant for Single Sign On (SSO).

Step 1: Create IdP in Console

Important: Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Important: Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org on Controller) can decrypt the SAML assertion.

Step 2: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your PingOne SAML application. Provide the following information to your PingOne administrator.

Step 3: Create Application in PingOne

Step 4: Configure Application Details in PingOne

In the Application Details page:

Step 5: Configure SAML Application in PingOne

In the Application Configuration Page:

If Encrypted SAML Assertion is enabled in Step 1,

Step 6: Configure SSO Attribute Mapping for Group in PingOne

In SSO Attribute Mapping page:

The SSO Attribute Mapping configuration step for Groups is critical because it will ensure that PingOne will send the groups the user belongs to as part of the SSO process. We use the group information to transparently map users to the correct group/role.

Step 7: Configure SSO Attribute Mapping for sending user's email as NameID in PingOne

In PingOne, make sure to configure SAML Subject to use Email in the SSO Attribute Mapping page:

Step 8: Assign Groups to Application in PingOne

In Group Access page:

In the example above, the PingOne group "SystemAdmins" has been assigned to the Application in PingOne. Multiple PingOne users can be added/removed from this group.

An identical named group needs to be created in your Org. Ensure that this group is mapped to the appropriate Projects with the correct privileges. In the example below, the Group "SystemAdmins" is configured as an "Organization Admin" with access to all Projects.

Step 9: Specify IdP Metadata URL

In PingOne Review setup page: